TrustSink: How a Rogue External MFA Provider Steals Passwords
Varonis Threat Labs described the TrustSink technique: a high-privileged attacker registers a fake external authentication method (EAM) in Microsoft Entra and embeds a phishing password page into the legitimate login. The provider receives the password in plaintext and returns a valid signed token, so login completes without errors, and password changes do not remove the fake provider.
- High-privileged attacker registers fake EAM provider in Microsoft Entra
- Fake password page captures credentials in plaintext with timestamp and IP
- Provider returns signed JWT with acr possessionorinherence and amr hwk, login succeeds without errors
- Password reset does not remove provider — it intercepts the new password too
Read next
Security